Re: help

From: Malke (malke_at_nospoonnotreally.com)
Date: 10/10/04


Date: Sat, 09 Oct 2004 21:01:24 -0700

anonymous@discussions.microsoft.com wrote:

> can anyone help please give me some steps to take to get
> rid of a trojan horse on my pc please

Yes, lots of people in this newsgroup can. Unfortunately, you haven't
given us the slightest information with which to help you. Here are
general troubleshooting steps.

Scan with a current antivirus program (meaning a version not earlier
than 2003 using updated virus definitions)in Safe Mode. If you don't
have a current antivirus (for shame!), follow the steps regarding Trend
Micro's Sysclean which are below these general steps:

Remove spyware with Spybot Search & Destroy from
www.safer-networking.org and Ad-aware from www.lavasoftusa.com. Be sure
to update these programs before running them. These programs are free,
so run them both since they complement each other. It is best to run
antivirus and spyware removal tools in Safe Mode. You may also want to
run CWShredder and HijackThis from http://aumha.org/freeware.htm.
Although CWShredder is no longer being updated, it will still clean
older variants of the CoolWebSearch malware. A combination of
HijackThis and About:Buster (http://www.majorgeeks.com) works well in
removing homepage hijackers. Please read the instructions carefully.
Make sure you are able to see all hidden files and extensions (View tab
in Folder Options). Also, make sure you've visited Windows Update and
applied all security patches. Do not install driver updates from
Windows Update. Make sure you are running a firewall.

TrendMicro's Sysclean is a fairly extensive tool which has the advantage
of not needing to be installed. It requires two parts - the scanning
engine and the virus pattern files.

1. Create a new folder on your Desktop or the C: drive named something
useful like "Sysclean".
2. Go here and download the two parts of the program to that folder:

http://www.trendmicro.com/download/dcs.asp - Sysclean
http://www.trendmicro.com/download/pattern.asp - virus pattern files

3. Restart your computer in Safe Mode. Get into Safe Mode by repeatedly
tapping the F8 key as the computer is starting up to get to the proper
menu.
4. Go to the Sysclean folder you made and double-click on sysclean.com.
Start the scan. After the scan is finished, look at the log. You may
need to make a note of where any viruses were found if they were not
able to be removed so you can manually delete them.

You should download all tools from a computer unconnected to the
infected pc, which computer needs a cd burner. You should take the
infected pc off all networks, including the Internet, and keep it off
until it is clean.

Malke

-- 
MS-MVP Windows User/Shell
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic"


Relevant Pages

  • Re: Virus killed my machine
    ... > just to load up to the desktop. ... > I can however start up in Safe Mode. ... Sysclean - TrendMicro's Sysclean is an extensive antivirus tool which ... Create a new folder on your Desktop or the C: ...
    (microsoft.public.windowsxp.security_admin)
  • Re: net controller 1.08 trojan
    ... > TrendMicro's Sysclean is an extensive antivirus tool which has the ... > scanning engine and the virus pattern files. ... Create a new folder on your Desktop or the C: ... Restart your computer in Safe Mode. ...
    (microsoft.public.windowsxp.general)
  • RE: XP Problem cant open Task Manager and a few others
    ... >> There are no System Restore points before this happened. ... Download TrendMicro's Sysclean, burn to cd-r, and take it to the sick ... Create a new folder on your Desktop or the C: ... Restart your computer in Safe Mode. ...
    (microsoft.public.windowsxp.general)
  • Re: Internet Traffic
    ... > off system restore, and restart in safe mode to delete these files. ... TrendMicro's Sysclean is an extensive antivirus tool which has the ... Create a new folder on your Desktop or the C: ... Restart your computer in Safe Mode. ...
    (microsoft.public.security.virus)
  • Re: windows xp new files and missing files help
    ... TrendMicro's Sysclean is an extensive antivirus tool which has the ... Create a new folder on your Desktop or the C: ... the most recent System Restore point from the More ... Do not install driver updates from Windows Update; ...
    (microsoft.public.windowsxp.general)